19.11.2016, 15:10
Quote:
%e |
SA:MP doesnt escape strings anywhere since its not built specially for SQL. Same as most programming/scripting languages.
There are many types of SQL injections therefore forbing characters straight on by SA:MP would be somewhat impossible.
Example:
Quote:
SELECT fieldlist FROM table WHERE field = 'x' AND email IS NULL; -- |
Also, as far as I know most of the special characters that you would use to do a injection attack are impossible to be added as a default name in SA:MP but there are advanced SQL injection attacks that can easily slip between those. Always escape your querries.